CVE Vulnerabilities

CVE-2022-32741

Published: Jun 13, 2022 | Modified: Jun 22, 2022
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Attacker is able to determine if the provided username exists (and its valid) using Request New Password feature, based on the response time.

Affected Software

Name Vendor Start Version End Version
Otrs Otrs 7.0.0 (including) 7.0.35 (excluding)
Otrs Otrs 8.0.0 (including) 8.0.23 (excluding)

References